Aruba ClearPass vs Forescout Platform vs Fortinet FortiNAC comparison

Cancel
You must select at least 2 products to compare!
HPE Aruba Networking Logo
19,466 views|13,272 comparisons
95% willing to recommend
Forescout Logo
11,070 views|6,547 comparisons
87% willing to recommend
Fortinet Logo
11,991 views|7,783 comparisons
86% willing to recommend
Comparison Buyer's Guide
Executive Summary

We performed a comparison between Aruba ClearPass, Forescout Platform, and Fortinet FortiNAC based on real PeerSpot user reviews.

Find out what your peers are saying about Cisco, HPE Aruba Networking, Fortinet and others in Network Access Control (NAC).
To learn more, read our detailed Network Access Control (NAC) Report (Updated: March 2024).
767,319 professionals have used our research since 2012.
Q&A Highlights
Question: Comparison of Aruba Clearpass, Bradford Networks and Forescout NACs
Answer: Thank for your nice works. I am working on the similar type comparison between Fortescout, FortiNAC(Bradford) and ISE for a project in a healthcare organization.
Featured Review
Quotes From Members
We asked business professionals to review the solutions they use.
Here are some excerpts of what they said:
Pros
"The most valuable feature of Aruba ClearPass is the ease of deployment and integration with other equipment in the network.""Its clustering model saved us staff time and reduced errors by eliminating the need to manage individual RADIUS servers.""Gives us network access control, visibility, scalability, security, and control in what is becoming an uncontrollable, inundated BYOD and IoT world.""It eliminated the management of 10 different individual discrete RADIUS servers.""What I like most about Aruba ClearPass is its access tracker that serves as its monitoring feature. The access tracker is really helpful when you want to troubleshoot authentication failures.""Aruba ClearPass is a simple solution for customers to see what is happening on their network.""What I like best about Aruba ClearPass is its 802.1X certificate-based authentication feature.""The initial setup was straightforward."

More Aruba ClearPass Pros →

"Forescout Platform has made it possible to block people working near our construction sites who should not have access to our network.""I have noticed that in the last year the license model has changed from licensing the whole appliance to licensing the number of devices. It's more simple for a large installation, or a user to have CounterACT as their peripheral site in the company. It's a good choice to have changed the license policy.""The best parts of Forescout Platform are its orchestration features, discovery capabilities, classification buckets, and flexibility in creating policies.""It allows for good detection of all the vendor products we have on-site.""Forescout Platform's most valuable features are that it is very granular. We are able to cull out a lot of information about our particular device or endpoint. The configuration and the visibility are very seamless. Overall the solution is very easy to handle and it's very comprehensive.""Vulnerability remediation is valuable. We can narrow down a system and its properties. We can go granular on the properties of each endpoint, such as which operating system you're using.""The product is very easy to work with and easy to deploy.""The most valuable features of the Forescout Platform are NAC for sharing, Network Access Control, and port sharing of the devices."

More Forescout Platform Pros →

"The initial setup was easy and straightforward.""This solution is very easy to implement and use. The interface is user-friendly.""The network segmentation is the most important part of the solution. The integration with the Zero Trust Access solution is a crucial part of segmenting your network.""The users say that FortiNAC is configurable and easy to use.""Fortinet FortiNAC has good user account customization.""The FortiNAC features I found the most valuable are security and the ability to consolidate wireless networks.""The most valuable aspect of Fortinet FortiNAC is the control it offers.""The support responds to our queries within two to four hours."

More Fortinet FortiNAC Pros →

Cons
"The setup of ClearPass can be a bit convoluted at times.""The platform's API integration could be better. Additionally, its pricing could be affordable.""The initial setup was quite complex, it is not that easy.""The GUI of Aruba ClearPass could improve, it is not user-friendly.""​​The AirWave Dashboard heat maps could be better designed.""The implementation can improve because it is challenging to explain some of the concepts to the client.""Aruba ClearPass has fewer deployment scenarios and flexibility than Forescout.""ClearPass' GUI could be more user-friendly."

More Aruba ClearPass Cons →

"The solution needs more definitive pricing. The costs are hard to nail down.""Definitely, having more third-party integration would be an improvement.""Can be expensive if it's only being used for one feature.""Forescout needs to upgrade its development in the future.""When we automate an email to send to a user, sometimes it gets blocked, but that has nothing to do with Forescout. It depends on the mail gateway that we use or integrate with.""It's scalable, but not without a big investment. It doesn't do so well at the branch. At the home office, it does okay and not so well at the branch.""Forescout needs to improve its cloud management and remote connectivity.""The licensing costs are quite high. With the amount of hardware we have, we need too many licenses to make the product effective and it's ultimately just too costly."

More Forescout Platform Cons →

"One of the biggest issues with Fortinet FortiNAC is that it is not intuitive and has a high learning curve.""The deployment of Fortinet FortiNAC could be better. When we are deploying the solution we have some level of dependencies with other vendors for their connection to Fortinet FortiNAC. Without these dependencies, it would be better.""The user interface and the product's intuitiveness could be improved.""The product could be more user-friendly in terms of GUI.""The interface works fine, but it could be better.""Fortinet's local support could be improved.""The GUI is a little bit strange — different than other Fortinet products.""I hope that Fortinet can add a feature with a remediation mechanism when you find a broken piece so that you can click on something and download the needed update or resolve the firewall issue more easily. Currently, we have to use an external remediation server to download updates."

More Fortinet FortiNAC Cons →

Pricing and Cost Advice
  • "Licensing and pricing are extremely straightforward."
  • "Run a 90 day free Proof of Concept (POC) for each product by implementing and using it fully in your environment. This way you will be educated on its features, functionality, and manageability.​"
  • "​Cost is important. I switched because Aruba's costs were well below Cisco's."
  • "We pay an annual licensing fee for Aruba and there are no additional costs."
  • "The pricing is not bad and everything is included."
  • "It is affordable. In Lebanon, companies are small, and they do not have a big budget. They cannot invest a lot of money, and Aruba ClearPass is quite affordable for them."
  • "The licensing model is very straightforward. There are two types of licensing for Aruba ClearPass, a perpetual license, and a subscription. Both of them are straightforward. We don't need to read an ordering guide, it's very clear."
  • "Aruba is a little more expensive than other products in the market here."
  • More Aruba ClearPass Pricing and Cost Advice →

  • "Devices with multiple IP's count multiple times against your license count."
  • "The fact that we were allowed to spin up as many servers as we had need of to support our geographic requirements while paying for licensing as an enterprise truly set Forescout apart from the crowd and improved the way we could design our access."
  • "We went with the virtual appliance option. The biggest cost to running these types of appliances would be to either have multiple virtual appliances at every data center or running Remote SPAN hardware to provide you the real-time network visibility."
  • "The ROI is priceless."
  • "It might not be the cheapest solution, but you get what you pay for."
  • "Time savings in finding rogue devices as well as identifying potentially unwanted devices on the network has saved the organization time and money."
  • "The setup cost, pricing, and licensing are on the high side."
  • "Forescout Platform is too expensive, so the price should be reduced."
  • More Forescout Platform Pricing and Cost Advice →

  • "It's a subscription-based license, which is based on the usage and number of concurrent users."
  • "The licensing fees are a little bit high."
  • "The pricing is similar to that of other solutions."
  • "The price of the license required is based on how many users are going to be using the solution. If you want more users you can upgrade your license."
  • "For the projects that we do the Fortinet FortiNAC is affordable."
  • "It's a pricey solution."
  • "The solution is expensive. However, it is not as expensive as other solutions, such as Cisco ISE."
  • "The price of Fortinet FortiNAC is less than Cisco's solution. However, the price could improve by being reduced."
  • More Fortinet FortiNAC Pricing and Cost Advice →

    report
    Use our free recommendation engine to learn which Network Access Control (NAC) solutions are best for your needs.
    767,319 professionals have used our research since 2012.
    Answers from the Community
    Anonymous User
    Eliu Rodriguez - PeerSpot reviewerEliu Rodriguez
    User

    Hi Nkwa,

    I did some research comparing ForeScout with ClearPass.
    Fundamentally they do the same but in a very different ways. It is important to understand these differences and how they could help you to achieve or not what you need in your organization. I will only point these differences and not every single detail. This is based on my own experience and I do not represent either ForeScout or Aruba ClearPass.

    DISCOVERY PROCESS / Profiler - METHODS.
    • NetFlow or SFlow: ForeScout do not support Sflow only NetFlow. Is this important? Yes, it is if your switches are not Cisco or any other vendor that support the NetFlow protocol.

    ForeScout says: "This capability becomes more relevant in large scale deployments, where the CounterACT packet engine is limited in its "ability to detect activity in remote sites and branch offices". Use of information reported by NetFlow improves visibility and speeds detection of new endpoints." Reference: https:\www.forescout.com\wp-content\uploads\2018\04\CounterACT_NetFlow_1.2.pdf Page 3.

    ClearPass:
    NetFlow V5/V9 and V10 aka IPFIX + sFLOW are supported.
    Reference: https://www.arubanetworks.com/techdocs/ClearPass/CP_ReleaseNotes_6.6.3/Content/WhatsNew/NewFeatures_ProfilerNWDiscovery.htm

    ORCHESTRATE = Integration/Collaboration with other Systems.
    ForeScout:

    * ForeScout
    is able to interchange contextual information with 3rd party solutions, however the most of the contextual collaboration capabilities are available using an Extended Module option and ForeScout charges separately for this.
    Reference Links:
    https://www.forescout.com/platform/extended-modules/#cmt
    https://www.cdw.com/product/forescout-extended-module-for-palo-alto-networks-next-generation-firewall/4589573
    https://www.cdw.com/search/?key=forescout&searchscope=all&sr=1

    Clear Pass:
    * 140+ Integrations are included as part of the core solution. Basically, you can integrate ClearPass to anything in your IT infrastructure at no extra cost to share contextual information. Firewalls, MDM, TicketSystem, SIEM, etc.. Using build-in Modules or APIs. You can request as well customized APIs.
    Reference Link https://www.arubanetworks.com/partners/programs/security-exchange/
    Reference Link https://www.arubanetworks.com/assets/so/SO_ClearPassExchange.pdf

    AGENT OR AGENTLESS?
    Basically, an agent based solution needs a software installed, while an agentless approach don't.
    Independently of what NAC solution you will use, it is important to understand if you need or not an agent.

    When a device connects to a network, the agent software performs some actions that have been defined in a central access controller or policy management platform. If persistent, the agent performs auto-remediation functions during a connection and will permanently monitor the device throughout a session to “fix” things that may change.
    The dissolvable agent: a user clicks on a web portal link to download the agent, which authenticates the user and device, checks the endpoint for compliance, and allows access to the network if policy conditions are met. It then disappears until the user runs it again.

    ForeScout
    ForeScout is proud to claim that they don’t require an agent (agentless approach NAC) but this is not completely true. ForeScout needs a “dissolvable agent” for authorization & compliance of unmanaged assets e.g. Employee BYOD, Contractor Laptops, printers, CCTV cameras, Smart TVs, etc. Agentless is fine when all your devices are Windows and all of them are under your management. For none windows devices you will need the dissolvable agent to perform health check and remediation.
    Based on this explanation having an agent or not is irrelevant for most of the cases. there many identities sources from where you can extract contextual information to help the NAC to do his work, examples are: AD, Wireless AP, End-Point protection software, SCCM, MDM, the Switches, the Firewall, etc...
    To do this you need integration, this is possible with ForeScout using the extended module /Plugins and normally paying the extra cost.
    Reference Link: https://www.forescout.com/wp-content/uploads/2018/08/Agentless-Visibility-and-Control-ForeScout-White-Paper.pdf

    ClearPass
    Clear pass can run with an agent and without the agent. It hast the persistence option, the dissolvable option for BYOD and Guest devices. It can be easily integrated to the mentioned identity stores at no extra cost.

    https://www.bradfordnetworks.com/agent-based-agent-less-other-understanding-the-different-ways-to-enable-nac/
    http://community.arubanetworks.com/t5/Technology-Blog/When-and-why-agents-for-NAC-It-s-not-a-Secret/ba-p/256672
    https://community.extremenetworks.com/extreme/topics/nac-vs-seperate-radius-server

    802.1X RADIUS AUTHENTICATION OR NOT

    Here is one of the major differences. Both support Radius authentication. ClearPass see it like the most secure way to protect your network and ForeScout see it like something complex that you should try to avoid if possible, in my opinion.

    ForeScout

    * says: 802.1X presents several deployments, operational and troubleshooting challenges, particularly on wired networks.
    * To perform RADIUS-based network authentication you need a “Plugin” to forward the authentication requests to an external authentication Sever, like the Microsoft NPS. Page 10, Reference link , you will need as well a Switch Plugin for wired network RADIUS-based deployment and a Wireless plugin for wireless network RADIUS-based deployment. All this sounds like a complexity to me.

    * By not having 802.1x configured you save also configuring all switches on your network. Which is not a big problem because you do this once during the useful life of the switch.

    * Not build-in TACACS+ - centralized remote authentication to network devices like switches, routers, etc.
    Reference Link:
    https://www.forescout.com/wp-content/uploads/2018/04/CounterACT_RADIUS_4.3.pdf

    ClearPass:
    * Is build-in CA and if you like you can use an external CA as well.
    * Centralizing the radius authentication make the administration and configuration very easy because you don’t have to manage the NAC and the CA separated.
    * No plugin is needed for non-802.1x Auth and non-domain joined devices. In this case you can enforce machine authentication and many other security layers to allow non-domain devices to safely connect without a certificate.
    * non-domain devices can automatically or manually be provisioned using a guest network and dissolvable agent.
    * Integration with the Aruba Wireless system for Radius Authentication is very easy (if you own an Aruba Wireless Infrastructure) and no extra cost.

    You must configure your switches to work with 802.1x. This can be easily done using a template on HPE IMC.
    • Build in TACACS+

    DEPLOYMENT AND INITIAL POLICY SETUP:

    ForeScout: preferred method is: I let you in then I find out who you are.

    • ForeScout CounterACT propose the Post-connect deployment strategy for network visibility and access control in which endpoints are initially allowed access to the network while CounterACT profiles them to determine ownership and compliance. Access to the network is then adjusted based on profiling results and security policy.
    Reference link: https://www.forescout.com/wp-content/uploads/2016/12/CounterACT-Deployment-Guide-Wired-Post-Connect.pdf

    This makes sense on new deployments because the NAC can be configured transparent to the end user with no dramatic impact. My question is: What is the process after deployment? Do I let you in then I find a good policy for you?

    ClearPass: preferred method is: I let you in if you tell me something about you. Then depending on the roles/policies this unknown device will be moved to a quarantine VLAN for remediation or moved to a dead end VLAN. At the same time this will trigger a ticket to helpdesk and a message to the user to know what is happening and what is the next step.

    SUPPORT, SERVICE and DOCUMENTATION:

    ForeScout:
    • The references are very good everywhere you read in internet. Also, the expertise of their engineers. You can browse a little and it won't be hard to find references.
    Online support, documentation, communities (forescout Chatter), etc.

    Aruba/HPE
    The references are very good everywhere you read in internet. Also, the expertise of their engineers. You can browse anywhere on internet and it won't be hard to find references.
    Online support, documentation, communities (aruba airheads), etc.

    PRICE:
    This will depend on many factors. I would suggest that you consult both and make your own decision.

    Questions from the Community
    Top Answer: Aruba ClearPass is a Network Access Control tool that gives secure network access to multiple device types. You can… more »
    Top Answer:I've done quite a lot of work with ClearPass, and not a lot with FortiNAC/Bradford. ClearPass incorporates a number of… more »
    Top Answer:If you are looking at the base installation, then it was a very straightforward process, which I would rate an eight or… more »
    Top Answer:Forescout is a very powerful NAC product that does not rely on port level configuration. It can detect and block… more »
    Top Answer:I would rate the Forescout Device and Visibility Control Platform at a six out of ten.
    Top Answer:I recommend doing a compression demo. If people use it, they will buy it. So they have to see the product in place… more »
    Top Answer:Cisco ISE uses AI endpoint analytics to identify new devices based on their behavior. It will also notify you if someone… more »
    Top Answer:The most valuable aspect of Fortinet FortiNAC is the control it offers.
    Top Answer:The product itself is inexpensive, but the licensing is expensive.
    Ranking
    Views
    19,466
    Comparisons
    13,272
    Reviews
    29
    Average Words per Review
    428
    Rating
    8.4
    Views
    11,070
    Comparisons
    6,547
    Reviews
    21
    Average Words per Review
    439
    Rating
    8.3
    Views
    11,991
    Comparisons
    7,783
    Reviews
    19
    Average Words per Review
    389
    Rating
    8.1
    Comparisons
    Also Known As
    Avenda eTIPS
    Forescout Platform, CounterACT for Endpoint Compliance, ForeScout CounterACT
    FortiNAC, Bradford Networks, Bradford Networks Sentry, Network Sentry Family
    Learn More
    Overview

    Aruba ClearPass is a network access control (NAC) solution that provides a range of security and access management capabilities for wired, wireless, and VPN networks. ClearPass enables organizations to secure their networks and devices, enforce security policies, and provide secure access to network resources.

    Aruba ClearPass Features

    Aruba ClearPass has many valuable key features. Some of the most useful ones include:

    • Device profiling: Aruba ClearPass automatically profiles and classifies network devices based on type, manufacturer, operating system, and more, to help organizations secure their networks.
    • Guest management: The solution provides a secure and easy-to-use guest management system for organizations to provide guest access to their networks.
    • User-friendly interface: The Aruba ClearPass includes a user-friendly interface, enabling administrators to easily manage and enforce security policies, monitor network activity, and respond to security threats.
    • Policy enforcement: Users can enforce security policies based on device type, user role, and other factors, to help secure their networks and devices.
    • Threat detection and response: With its real-time monitoring and threat detection capabilities, organizations are able to quickly identify and respond to security threats.
    • Authentication and authorization: Aruba ClearPass offers a range of authentication and authorization methods, including certificate-based authentication and 802.1X, to provide secure access to network resources.
    • Reporting and analytics: The solution Includes real-time reporting and analytics capabilities, enabling administrators to monitor network activity, track security incidents, and improve security over time.

    Aruba ClearPass Benefits

    There are many benefits to implementing Aruba ClearPass. Some of the biggest advantages the solution offers include:

    • Comprehensive solution: Aruba ClearPass integrates with a range of network security technologies, including firewalls, intrusion detection and prevention systems, and VPN gateways, to provide a comprehensive security solution.
    • Scalability: Designed to scale from small to large organizations, ClearPass provides a solution that can grow with an organization's needs.
    • Increased visibility: By implementing Aruba ClearPass, administrators can monitor network activity, track security incidents, and improve security over time.
    • Improved user productivity: The solution’s secure and seamless access to network resources helps users be more productive and access the resources they need, when they need them.
    • Better business agility: With the solution, organizations can quickly respond to security threats and enforce security policies, improving overall business agility.

    Reviews from Real Users

    Aruba ClearPass is a solution that stands out when compared to many of its competitors. Some of its major advantages are that it’s easy to use, has a valuable Guest Captive Portal and virtual security enforcement, and has a good web dashboard and policy manager.

    “It is easy to use and more integrated with the Aruba wireless networks,” says Muhammad N., Network & Information Security Engineer at a healthcare company.

    Ammar F., Head of IT at Hubtech, explains, “What I like most about Aruba ClearPass is that it has the best enforcement feature for the network. I also like its Guest Captive Portal and virtual security enforcement features, but the virtual security enforcement feature is still under testing by my company. Aruba ClearPass also has a wonderful UI which I find valuable."

    Another PeerSpot reviewer mentions, "The web dashboard and the policy manager are very intuitive and very easy for the engineers to use."

    Forescout Platform provides today’s busy enterprise organizations with policy and protocol management, workflow coordination, streamlining, and complete device and infrastructure visibility to improve overall network security. The solution also provides concise real-time intelligence of all devices and users on the network. Policy and protocols are delineated using gathered intelligence to facilitate the appropriate levels of remediation, compliance, network access, and all service operations. Forescout Platform is very flexible, integrates well with most of today’s leading network security products, and is a very cost-effective solution.

    Forescout Platform Features

    • Real-time complete visibility: With Forescout eyeSight, each and every device is classified when any attempt to access your network has been made. This includes - but is not limited to - desktops, laptops, android devices, virtual machines, switches, VoIP phones, USB memory sticks, webcams, IoT devices, and more.

    • Policy-based and manual controls: In today’s busy robust environment, networks are continually changing; there are different types and amounts of devices connected, various software applications, network compliance requirements, and the constant potential for risk make managing an IT network a very daunting challenge. The Forescout Console is used to simplify the administration and management of important alerts, remediation, and access controls to keep the network secure.

    • Intuitive real-time dashboards: Forescout Dashboards, a component of Forescout WebClient, is a comprehensive web-based intelligence center that gives full visibility and real-time insight of the complete network using both out-of-the-box and user-created widgets. The dashboards are very intuitive and deliver robust, easy-to-understand information about device visibility, compliance, health monitoring, and more.

    • Advanced reporting capabilities: The Forescout Reports Plugin will generate numerous valuable reports indicating real-time and overall status information about endpoint compliance, device details, networks guests, protocols, and more. The reports help to ensure IT administrators, executives, security teams, and other important shareholders stay well-informed about all network activity at all times.

    • Comprehensive third-party overview: Forescout eyeExtend facilitates seamless information sharing with third-party vendors, networks, and IT management solutions supporting improved automated workflows, productivity, cost-effectiveness, and overall security.

    Real User Reviews

    An important main feature of Forescout is the visibility the solution offers.

    One reviewer who is a Consultant at a tech services company, says, "Within three or four days, you can have complete visibility of your infrastructure on the network. Compared to other solutions, the deployment of the solution is easier and we can close the project quickly."

    Users also appreciate that the user interface is clear and easy to understand.

    An Instructor at a tech services company, shares, "The most valuable feature of the Forescout Platform is the large capacity it can handle. Additionally, the interface of the platform is good."

    Fortinet's FortiNAC is a network access control solution that provides visibility, control, and automated response for everything that connects to the network, enhancing the security fabric. FortiNAC protects against Internet of Things (IoT) threats, extends control to third-party devices, and orchestrates automated responses to a variety of networking events.

    Using many information and behavior sources, FortiNAC delivers extensive profiling of even headless devices on your network, allowing you to precisely identify what's on your network.

    You can change the configurations of switches and wireless equipment from more than 70 vendors to implement micro-segmentation regulations. You can also extend the security fabric's reach in diverse contexts.

    With FortiNac, you can respond in seconds to events in your network to stop attacks from spreading. When the relevant behavior is seen, FortiNAC offers a rich and customized set of automation policies that can rapidly trigger configuration changes.

    Fortinet FortiNAC Features

    Fortinet FortiNAC has many valuable key features. Some of the most useful ones include:

    • Agent or agentless (automated) scanning of the network for device detection and classification
    • Generates a list of all the devices on the network.
    • Evaluates the risk of each network endpoint.
    • Consolidates the architecture to make deployment and management easier
    • Gives wide support for third-party network devices to maintain compatibility with current network infrastructure,
    • Automates the process of onboarding a large number of endpoints, users, and visitors.
    • Enables network segmentation and enforces dynamic network access restriction.
    • Reduces the time it takes to contain a problem from days to seconds.
    • Reduces investigation time by reporting events to SIEM with detailed contextual data.

    Fortinet FortiNAC Benefits

    There are many benefits to implementing DX Spectrum. Some of the biggest advantages the solution offers include:

    • Automatic response: FortiNAC will continuously monitor the network, analyzing endpoints to ensure they meet their profile. FortiNAC will rescan devices to verify that MAC-address spoofing does not compromise the security of your network access. FortiNAC can also keep an eye out for unusual traffic patterns. The FortiGate appliances are used in conjunction with this passive anomaly detection. When a compromised or vulnerable endpoint is identified as a threat, FortiNAC initiates a real-time automatic response to confine the endpoint.

    • Total device visibility: FortiNAC monitors the entire network and provides total visibility. FortiNAC searches your network for users, applications, and devices. FortiNAC may then profile each element based on observed attributes and reactions, as well as drawing on FortiGuard's IoT Services, a cloud-based database for identification look-ups, using up to 21 distinct techniques.
    • Dynamic network management: Once the devices and users have been identified, FortiNAC allows for extensive network segmentation to allow devices and users access to critical resources while preventing unauthorized access. FortiNAC employs dynamic role-based network access control to conceptually establish network segments by grouping similar applications and data together to restrict access to a certain set of users and/or devices. If a device is compromised in this way, its capacity to travel through the network and target other assets is constrained. FortiNAC assists in the protection of sensitive data and assets while maintaining compliance with internal, industry, and government standards and directives. Assuring the integrity of devices before they join the network reduces the chance of malware spreading.

    Reviews from Real Users

    Fortinet FortiNAC stands out among its competitors for a number of reasons. Two major ones are its robust network segmentation and its device visibility. PeerSpot users take note of the advantages of these features in their reviews:

    A Senior Proposal Manager at a tech services company writes of the solution, “The network segmentation is the most important part of the solution. The integration with the Zero Trust Access solution is a crucial part of segmenting your network.”

    Eranjaya K., Security Engineer at Eguardian lanka, notes, “We use Fortinet FortiNAC to receive excellent visibility of our network for traffic and what devices are connected to prevent attacks.” He adds, “I have found Fortinet FortiNAC to be scalable.”

    Sample Customers
    Consulate Health Care, Los Angeles Unified School District, Science Applications International Corp (SAIC), San Diego State University, KFC, ACTS Retirement-Life Communities
    NHS Sussex, SAP, SEGA, Vistaprint, Miami Children's Hospital, Pioneer Investments, New York Law School, OmnicomGroup, Meritrust
    Isavia, Pepperdine University, Medical University of South Carolina, Columbia University Medical Center, Utah Valley University
    Top Industries
    REVIEWERS
    Comms Service Provider18%
    Computer Software Company18%
    Manufacturing Company11%
    Healthcare Company11%
    VISITORS READING REVIEWS
    Computer Software Company17%
    Government9%
    Manufacturing Company7%
    Comms Service Provider7%
    REVIEWERS
    Financial Services Firm17%
    Government12%
    Manufacturing Company10%
    Computer Software Company10%
    VISITORS READING REVIEWS
    Educational Organization29%
    Computer Software Company11%
    Government8%
    Financial Services Firm7%
    REVIEWERS
    Comms Service Provider24%
    Financial Services Firm16%
    Computer Software Company16%
    Manufacturing Company12%
    VISITORS READING REVIEWS
    Educational Organization32%
    Computer Software Company12%
    Comms Service Provider6%
    Government5%
    Company Size
    REVIEWERS
    Small Business42%
    Midsize Enterprise23%
    Large Enterprise35%
    VISITORS READING REVIEWS
    Small Business23%
    Midsize Enterprise17%
    Large Enterprise60%
    REVIEWERS
    Small Business37%
    Midsize Enterprise12%
    Large Enterprise51%
    VISITORS READING REVIEWS
    Small Business14%
    Midsize Enterprise36%
    Large Enterprise50%
    REVIEWERS
    Small Business51%
    Midsize Enterprise23%
    Large Enterprise26%
    VISITORS READING REVIEWS
    Small Business19%
    Midsize Enterprise43%
    Large Enterprise38%
    Buyer's Guide
    Network Access Control (NAC)
    March 2024
    Find out what your peers are saying about Cisco, HPE Aruba Networking, Fortinet and others in Network Access Control (NAC). Updated: March 2024.
    767,319 professionals have used our research since 2012.